CVE-2015-2239
Google Chrome before 41.0.2272.76, when Instant Extended mode is used, does not properly consider the interaction between the "1993 search" features and restore-from-disk RELOAD transitions, which makes it easier for remote attackers to spoof the…
Does this matter?
Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.
Description
Google Chrome before 41.0.2272.76, when Instant Extended mode is used, does not properly consider the interaction between the "1993 search" features and restore-from-disk RELOAD transitions, which makes it easier for remote attackers to spoof the address bar for a search-results page by leveraging (1) a compromised search engine or (2) an XSS vulnerability in a search engine, a different vulnerability than CVE-2015-1231.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.15% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-19
- Affected
- google/chrome
- Source
- cve@mitre.org
References
- http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.htmlVendor Advisory
- http://www.securityfocus.com/bid/74855
- https://code.google.com/p/chromium/issues/detail?id=256724Vendor Advisory
- https://code.google.com/p/chromium/issues/detail?id=463349
- http://googlechromereleases.blogspot.com/2015/03/stable-channel-update.htmlVendor Advisory
- http://www.securityfocus.com/bid/74855
- https://code.google.com/p/chromium/issues/detail?id=256724Vendor Advisory
- https://code.google.com/p/chromium/issues/detail?id=463349
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.